Conversation
Bump ethnum 1.5.0 -> 1.5.3 in packages/contracts so the contract crate compiles on the current stable toolchain (rustc 1.97.1). ethnum 1.5.0 fails with error[E0512] transmuting () into TryFromIntError, which no longer share a size; the crate fixed it in 1.5.1. Bump apps/api to Go 1.25.12 and golang.org/x/text v0.39.0 to clear the two govulncheck findings not in the allowlist: GO-2026-5856 (crypto/tls, fixed in go1.25.12) and GO-2026-5970 (x/text, fixed in v0.39.0).
… for chat/analyze (Suncrest-Labs#875) * feat(intelligence): add prompt-injection and output-safety guardrails Claude calls in the chat and analyze paths had no defense against prompt injection or system-prompt extraction, and recommendation output wasn't schema-enforced. Add input screening (regex-based, logs request_id + a non-reversible fingerprint, never raw content), a hardened system prompt with an explicit trust boundary and tagged untrusted-content wrapping, deterministic history/message bounding, and output post-processing that strips leaked system-prompt text and enforces a non-model-controlled disclaimer on /analyze and related endpoints. * fix(intelligence): close remaining guardrail gaps from review - Validate inbound X-Request-Id against a bounded safe charset before trusting it in state/headers/logs, falling back to a fresh UUID otherwise (prevents log/header injection via a client-supplied header). - Fix the chat streaming leak-redaction buffer to retain a sanitized lookback tail on flush instead of resetting to empty, so a system-prompt marker split across two deltas is still caught. - Wrap the remaining unwrapped context data interpolated into the recommend/vault and analyze prompts (positions, vault/user context lines) in the same trust-boundary tags used elsewhere. - Sanitize the few model-derived output fields that were missed: confidence_reason/data_freshness in Recommendation, insight card action.label/href, and deposit schedule note.
…ured output - Add goal_extractor service with Claude structured output - Add natural_language_goal router for API endpoints - Extract name, amount, deadline, category from natural language - Validate deterministically after extraction - Surfaces ambiguities for confirmation, never guess - Prompt injection resistant - Add comprehensive tests Closes Suncrest-Labs#853
✅ Deploy Preview for nesterhq canceled.
|
✅ Deploy Preview for nesterdapp ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
Warning Review limit reached
Next review available in: 35 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (21)
✨ Finishing Touches 💡 1⚔️ Resolve merge conflicts 💡
🧪 Generate unit tests (beta)
Comment |
|
Hey any updates? |
Summary
Adds natural-language goal creation using Claude structured output. Users can create savings goals by describing them in plain language.
Changes
goal_extractor.pyservice with Claude structured outputnatural_language_goal.pyrouter for API endpointsAPI Endpoints
POST /intelligence/extract-goal- Extract structured goal from natural languagePOST /intelligence/confirm-goal- Confirm and create the extracted goalSecurity
Closes #853